CVE-2025-36119 Information
Aug 09, 2025
cve
Description
IBM i 7.3 7.4 7.5 and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Reference
https://www.ibm.com/support/pages/node/7241008
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
LOW
Base Severity
7.1
Related CNNVD
CNNVD-202508-796 (Published: 2025-08-08)
Share on: